Subject: Re: PAM and OpenSSH
To: Jason Thorpe <thorpej@shagadelic.org>
From: Roland Dowdeswell <elric@imrryr.org>
List: tech-userlevel
Date: 01/26/2005 12:58:09
On 1106759066 seconds since the Beginning of the UNIX epoch
Jason Thorpe wrote:
>
>The complication here is that the SSH protocol itself has provisions
>for the Kerberos protocol. I seem to recall that in SSHv2, the
>Kerberos (GSSAPI, really) credentials are used for transport re-keying,
>as well.
Actually, there is old fashioned krb5 support in protocol 2 as well
as the GSSAPI support which we'll need to pull back in, also. So,
we'll need to support 3 Kerberos authentication methods.
--
Roland Dowdeswell http://www.Imrryr.ORG/~elric/